Review RDS collection access at the collection boundary

Which directory groups should be allowed into each RDS collection?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

Which directory groups should be allowed into each RDS collection?

Potentially affected

Administrators assigning user and group access to Remote Desktop Services collections.

DSE recommendation

Have each application owner approve the groups that should reach the collection and identify a reviewer for future membership changes.

Source facts

Microsoft documents separate collection access assignments so different user populations can receive different sets of applications. In the documented domain deployment, AD DS supplies the users and groups used for these assignments. After users and groups exist in the directory, administrators assign them to the intended Remote Desktop collections. Microsoft Learn.

Applicability

List the collections, application owners, and intended populations before changing membership or access settings. Review existing directory groups rather than creating a new group solely to match a collection name. Keep the collection-access decision separate from privileges inside an application or session.

DSE recommendation

Have each application owner approve the groups that should reach the collection and identify a reviewer for future membership changes. Record the collection-to-group mapping and the reason for any broad group. Use representative eligible and ineligible accounts in a pilot. Preserve the initial assignment list and agree on how access will be removed when a person changes roles.

Verification

Test access to the intended collection with each approved population and confirm that an excluded account does not gain access. Review another collection as a boundary check so a broad assignment does not go unnoticed. Verify the expected applications appear, then record membership, collection settings, and actual outcomes together.

Official references

Microsoft Learn: Manage users in your RDS collection. Source reviewed September 8, 2026.

Primary reference

Review the official source

Manage users in your RDS collection · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE